Paperthin

Commonspot Content Server

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.65%
  • Veröffentlicht 15.04.2014 23:13:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequences.

  • EPSS 0.9%
  • Veröffentlicht 15.04.2014 23:13:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.

  • EPSS 0.28%
  • Veröffentlicht 15.04.2014 23:13:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not check authorization in unspecified situations, which allows remote authenticated users to perform actions via unknown vectors.

  • EPSS 0.35%
  • Veröffentlicht 15.04.2014 23:13:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Incomplete blacklist vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted string, as demonstrated by bypassing a protection mechanism that removes ...

  • EPSS 0.2%
  • Veröffentlicht 15.04.2014 23:13:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to inject arbitrary web script or HTML via a crafted HTTP request to a (1) ColdFusion or (2) JavaScript component.

  • EPSS 0.35%
  • Veröffentlicht 15.04.2014 23:13:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a direct request.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 02.02.2010 17:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Cross-site scripting (XSS) vulnerability in utilities/longproc.cfm in PaperThin CommonSpot Content Server allows remote attackers to inject arbitrary web script or HTML via the url parameter.

Exploit
  • EPSS 4.38%
  • Veröffentlicht 29.12.2005 11:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Cross-site scripting (XSS) vulnerability in loader.cfm in PaperThin CommonSpot Content Server 4.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the bNewWindow parameter.

  • EPSS 0.4%
  • Veröffentlicht 29.12.2005 11:03:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

PaperThin CommonSpot Content Server 4.5 and earlier allow remote attackers to obtain sensitive information via an invalid errmsg parameter to loader.cfm with a url parameter set to email-login-info.cfm, which leaks the full pathname in the resulting ...